DrWhax of the Tails project reported that Claws Mail is missing range checks in some text conversion functions. A remote attacker could exploit this to run arbitrary code under the account of a user that receives a message from them using Claws Mail. For the oldstable distribution (wheezy), this problem has been fixed in version 3.8.1-2+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 3.11.1-3+deb8u1. We recommend that you upgrade your claws-mail packages.
DrWhax
of the Tails project reported that Claws Mail is missing
range checks in some text conversion functions. A remote attacker
could exploit this to run arbitrary code under the account of a user
that receives a message from them using Claws Mail.
For the oldstable distribution (wheezy), this problem has been fixed in version 3.8.1-2+deb7u1.
For the stable distribution (jessie), this problem has been fixed in version 3.11.1-3+deb8u1.
We recommend that you upgrade your claws-mail packages.